Trusted Execution Environment Key Migration via Certificate Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional key migration techniques in symmetric and asymmetric cryptography are overly reliant on complex hardware systems, lack specificity in controlling key migration, and are not suitable for non-local deployment environments, posing security risks and practical challenges in provisioning and trusting migration authorities.
Innovation Solution
A secure key management system using a Trusted Execution Environment (TEE) with a client and a Certificate Authority (CA) for secure key enrollment, export, and import, employing flags for migration authorization and Sigma protocol for secure channel establishment, allowing secure and targeted key migration without relying on physically moving hardware or manual PIN-based methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional key migration techniques are used, then key migration can be performed, but the system becomes overly reliant on complex hardware systems and lacks specificity in controlling key migration
Solution Approach 1:
The patent replaces complex hardware-based key migration systems with a software-based solution using Trusted Execution Environments (TEE). The TEE provides a secure virtual boundary that enables key migration through cryptographic operations rather than physical hardware manipulation, thereby reducing hardware complexity while maintaining security and increasing control specificity through software-defined policies.
Solution Approach 2:
The patent introduces a Migration Authority (MA) as an intermediary entity that mediates key migration between different TEEs. The MA uses cryptographic tokens and certificates to enable controlled key transfer without requiring direct hardware connections or manual intervention, thus simplifying the system architecture while providing fine-grained control over migration operations.
2Reliability
If manual PIN-based key migration methods are used, then key migration can be performed, but security risks increase and the method is not suitable for non-local deployment environments
Solution Approach 1:
The patent replaces manual PIN-based key migration with automated cryptographic operations within TEEs. The system uses machine-to-machine authentication through certificates and tokens, eliminating the need for human intervention and manual PIN entry. This substitution enhances security by removing human error vulnerabilities while improving deployment flexibility for non-local environments through automated remote key migration.
Solution Approach 2:
The TEE system performs self-service key migration operations by automatically generating cryptographic tokens, validating certificates, and executing key transfer protocols without requiring manual user input. The system autonomously manages the key migration process, including secure storage, encryption, and transmission, thereby improving both security and ease of operation in distributed environments.
3Reliability
If complex hardware systems are used for key migration, then key security can be maintained, but the infrastructure becomes overly complex and difficult to provision
Solution Approach 1:
The patent creates a universal key migration framework based on TEEs that can operate across diverse hardware platforms and deployment scenarios. The TEE provides a standardized secure boundary that works whether keys are stored locally or remotely, eliminating the need for different hardware systems for different deployment types. This universality simplifies infrastructure provisioning while maintaining security through a consistent cryptographic approach.
Solution Approach 2:
The Migration Authority serves as a universal intermediary that handles key migration for all TEEs regardless of their specific hardware implementation or deployment location. The MA uses standardized cryptographic protocols to mediate key transfer, eliminating the need for complex custom hardware provisioning for each scenario and simplifying infrastructure setup while maintaining security through centralized cryptographic control.
Data Source
AI summary
An embodiment includes a method executed by at least one processor of a first computing node comprising: generating a key pair including a first public key and a corresponding first private key; receiving an instance of a certificate, including a second public key, from a second computing node located remotely from the first computing node; associating the instance of the certificate with the key pair; receiving an additional instance of the certificate; verifying the additional instance of the certificate is associated with the key pair; and encrypting and exporting the first private key in response to verifying the additional instance of the certificate is associated with the key pair. Other embodiments are described herein.


